MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings
MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings imports and displays MLS real estate listings through IDX functionality in WordPress.
MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings (mlsimport-idx-plugin-mls-plugin-for-real-estate-listings) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 4.3.
mlsimport-idx-plugin-mls-plugin-for-real-estate-listingsCVE-2026-17515: MLSImport subscriber AJAX access exposes import logs and post metadata
MLSImport before 7.0.4 exposes an AJAX action without an authorization check or CSRF protection. Any authenticated user, including a Subscriber, can invoke it to read the plugin's import log and import-related metadata for arbitrary posts. This unscored record received deeper review because it gives a low-privilege account an information-disclosure primitive that may expose paths, import failures or listing metadata. The CNA does not disclose the AJAX action, parameters or handler function.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-17515
MLSImport subscriber AJAX access exposes import logs and post metadata
MLSImport before 7.0.4 exposes an AJAX action without an authorization check or CSRF protection. Any authenticated user, including a Subscriber, can invoke it to read the plugin's import log and import-related metadata for arbitrary posts. This unscored record received deeper review because it gives a low-privilege account an information-disclosure primitive that may expose paths, import failures or listing metadata. The CNA does not disclose the AJAX action, parameters or handler function.
|
7.0.4 |
CVE4.3
NVDPending
|